GHSA-8wgc-jjvv-cv6v

    Dashboard / Vulnerabilities / GHSA-8wgc-jjvv-cv6v

    GHSA-8wgc-jjvv-cv6v

    Published: 2 Sept 2020Last Modified: 27 Sept 2021

    Summary: Improper Authorization in loopback

    Details: Vulnerable versions of `loopback` may allow attackers to create Authentication Tokens on behalf of other users due to Improper Authorization. If the AccessToken model is publicly exposed, an attacker can create Authorization Tokens for any user as long as they know the target's `userId`. This will allow the attacker to access the user's data and their privileges. ## Recommendation For loopback 2.x, upgrade to version 2.40.0 or later For loopback 3.x, upgrade to version 3.22.0 or later

    Affected packages

    Package

    Name: loopback

    Purl: pkg:npm/loopback

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.40.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-8wgc-jjvv-cv6v | CVE-DB